Privacy Policy
Last updated: 8 September 2026
This notice describes how personal data is processed through securopera.com under Articles 12 and 13 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree No. 196 of 30 June 2003, as amended (the “Italian Data Protection Code”).
1. Data Controller
SecurOpera Consulting S.r.l.
Via Antonio Gramsci 22, 50019 Sesto Fiorentino (FI), Italy
VAT number and tax code: 06552890482
Florence Companies Register, REA FI-637518
Share capital: €10,000, fully paid up
Email: info@securopera.com
2. Data processed
- Browsing data and technical logs: data normally transmitted by browsers and Internet systems, such as the IP address, date and time of the request, requested resource and browser or device information, as needed to deliver and protect the website.
- Contact-form data: name, email address and message are required; the telephone number is optional.
- Subsequent communications: any additional information supplied by the data subject while the request is handled.
- Internal search: if used, the words entered in the website search field and technical data connected with the request.
- Technical preferences: selected language, as described in the Cookie Policy.
The website also records aggregate counts of interactions with contact requests. This tracking uses neither cookies nor localStorage and is not used to create individual profiles.
3. Purposes and legal bases
- Replying to requests for information, contact or quotations and taking pre-contractual steps requested by the data subject: Article 6(1)(b) GDPR.
- Complying with legal, accounting or tax obligations and lawful requests from authorities: Article 6(1)(c) GDPR.
- Ensuring website and system operation, continuity, abuse prevention and security, including technical-log management and the establishment, exercise or defence of legal claims: the Controller’s legitimate interests under Article 6(1)(f) GDPR, balanced against the rights and freedoms of data subjects.
- Managing language preferences and technical functions requested by users: service operation and legitimate interests under Article 6(1)(f) GDPR; access to the device is limited to technical tools exempt from consent where Article 122 of the Italian Data Protection Code so provides.
The website does not process data for marketing, behavioural advertising or profiling and does not carry out decisions based solely on automated processing that produce legal or similarly significant effects.
4. Provision of data
Name, email address and message are required to submit and handle a request; without them, SecurOpera cannot reply. A telephone number is optional. Consent is not requested to reply to a request or to take pre-contractual steps requested by the data subject.
Do not enter health data, data concerning criminal convictions or offences, or personal data about third parties that is not strictly necessary. If a matter requires such information, use only the channel and instructions specifically agreed with SecurOpera.
5. Processing methods and security
Data is processed electronically and, where necessary, through organisational procedures designed to restrict access to authorised persons. Technical and organisational measures proportionate to the risks are adopted; however, no system can guarantee absolute security.
6. Recipients
Within the limits of what is necessary, data may be made available to the following categories of recipients:
- the Controller’s authorised staff and collaborators;
- hosting, email, maintenance, security and IT-support providers, including providers of website and contact-form tools;
- professional, legal, tax, accounting or insurance advisers, where necessary;
- banks or administrative-service providers if a request leads to a contractual relationship;
- public authorities, law-enforcement bodies or other parties where disclosure is required by law or a lawful order.
Providers processing data on behalf of the Controller are appointed as processors under Article 28 GDPR where applicable. An updated list of processor categories may be requested from the Controller.
7. Technical services and external resources
Fonts are hosted and served directly by securopera.com, and public pages do not connect to Google Fonts or WordPress.org remote emoji resources. Hosting/CDN infrastructure and other technical providers may receive navigation data strictly necessary to deliver and protect the website, according to the applicable roles and safeguards. Google Analytics, Google Tag Manager, advertising pixels and reCAPTCHA are not active in the configuration described in this notice.
8. Transfers to third countries
If a recipient or provider processes data outside the European Economic Area, the transfer will take place in compliance with Articles 44 et seq. GDPR and will rely, as applicable, on an adequacy decision, standard contractual clauses approved by the European Commission or another safeguard provided by the GDPR, together with any supplementary measures required by the transfer assessment. Information about applicable safeguards may be requested from the Controller.
9. Retention
- Requests and communications: for the time needed to reply, carry out the requested pre-contractual activities and manage any follow-up, and thereafter for the further period required to document the activity and protect legal rights, taking applicable limitation periods into account.
- Data relating to a contractual relationship: for the duration of the relationship and thereafter for the period required by legal, accounting and tax obligations and the protection of rights.
- Technical and security logs: for a period proportionate to operation, security, abuse prevention, incident investigation and accountability needs, having regard to the nature and severity of the risk.
- Language preference: for the period stated in the Cookie Policy; users may delete it through their browser.
Data is erased or anonymised when its purpose ends, unless retention is required by law or is necessary in connection with a dispute.
10. Data-subject rights
Where Articles 15–22 GDPR apply, data subjects may request access, rectification, erasure, restriction and portability and may object to processing based on legitimate interests. These rights are not absolute and may be subject to statutory conditions and exceptions.
Requests may be sent to info@securopera.com. The Controller may request reasonable information to verify the requester’s identity.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) under Article 77 GDPR, or with the competent supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement.
11. References and updates
The main legal references are Regulation (EU) 2016/679, Italian Legislative Decree No. 196/2003 and, for cookies and similar tools, the Italian Data Protection Authority’s Guidelines of 10 June 2021.
This notice may be updated to reflect legal, organisational or technical changes. The updated version will be published on this page with its date.
Language note: this translation is provided for convenience. In the event of inconsistency, the Italian version shall prevail to the extent permitted by applicable law.